
Premmerce Variation Swatches for WooCommerce Security & Risk Analysis
wordpress.org/plugins/premmerce-woocommerce-variation-swatchesThis plugin flexibly extends standard features of the WooCommerce attributes and variations.
Is Premmerce Variation Swatches for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Premmerce Variation Swatches for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "premmerce-woocommerce-variation-swatches" v1.2.2 presents a mixed security posture. While the static analysis indicates a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks, there are areas of concern. The SQL query analysis reveals that only 79% use prepared statements, leaving a significant portion potentially vulnerable to SQL injection if input is not meticulously sanitized. Furthermore, only 70% of output is properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks is particularly worrying given the lack of other explicit authorization mechanisms on the identified entry points. The vulnerability history, while showing no currently unpatched CVEs, includes one high-severity vulnerability in the past, which was of the "Missing Authorization" type. This historical pattern, combined with the current lack of explicit capability checks in the static analysis, suggests a potential ongoing weakness in authorization enforcement.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not fully implemented
- No nonce checks
- Bundled Freemius library v1.0 outdated
- Past high severity vulnerability (Missing Auth)
Premmerce Variation Swatches for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Premmerce Variation Swatches for WooCommerce Release Timeline
Premmerce Variation Swatches for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Premmerce Variation Swatches for WooCommerce Attack Surface
WordPress Hooks 35
Maintenance & Trust
Premmerce Variation Swatches for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Premmerce Variation Swatches for WooCommerce Alternatives
Variation Swatches for WooCommerce
woo-variation-swatches
Beautiful Color, Image and Buttons Variation Swatches For WooCommerce Product Attributes
Variation Swatches for WooCommerce
product-variation-swatches-for-woocommerce
Variation Swatches for WooCommerce plugin adds button, Image, radio, and color swatches to your product attribute & enhance the product selection.
Variation Swatches for WooCommerce
woo-product-variation-swatches
Variation Swatches for WooCommerce change beautiful colors, images and buttons variation swatches for WooCommerce product attributes.
Swatchly – Product Variation Swatches for WooCommerce
swatchly
Product Variation Swatches For WooCommerce Products.
Variation Swatches for WooCommerce
th-variation-swatches
Variation Swatches for WooCommerce plugin will replace default swatches to professionally styled and colourful swatches.
Premmerce Variation Swatches for WooCommerce Developer Profile
14 plugins · 60K total installs
How We Detect Premmerce Variation Swatches for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/premmerce-woocommerce-variation-swatches/admin/css/style.css/wp-content/plugins/premmerce-woocommerce-variation-swatches/admin/js/script.jsHTML / DOM Fingerprints
premmerce-pwvs-settingsdata-attribute-idpremmerce_pwvs_admin